Back to Corporate Standards
CS-03 · Corporate Standards

Network Access Control Policy

Identity-aware, posture-aware access to all corporate networks.

DOCUMENT

CS-03

OWNER

Director of Network Security

EFFECTIVE

January 1, 2026

REVIEWED

April 1, 2026

Class · PUBLIC·Review cycle · Annual

Purpose

Alexa Cybersecurity operates a Zero-Trust network model. There is no implicit trust based on network location. Every connection — internal, remote, partner, or guest — is subject to identity verification, device posture validation, and continuous authorization.

This Policy implements NIST SP 800-207 (Zero Trust Architecture) and ISO/IEC 27001 A.8.20 (Network security).

Network zones

  • 01Production — customer-facing services and the systems that operate them. Access by approved engineers only, on managed devices, with MFA and just-in-time elevation.
  • 02Corporate — staff productivity and internal SaaS. Access requires a managed identity and device posture check.
  • 03Partner — segmented, tunnel-only access for vendors and integrators with contractual scope.
  • 04Guest — internet-only, with no path to internal resources; PSK rotated per visit.
  • 05Lab — research, malware analysis, and red-team work. Strictly air-gapped or token-mediated.

Access requirements

  • 01Multi-factor authentication on every authentication event — phishing-resistant factors required for production.
  • 02Device posture — full disk encryption, EDR running and reporting, OS within N-2 patch level, screen lock under 5 minutes.
  • 03Identity Provider single source of truth — no local accounts on production endpoints.
  • 04Least-privilege role assignments reviewed quarterly.
  • 05Privileged access via Just-in-Time elevation with session recording.

Continuous monitoring

All network access is logged and forwarded to the SIEM with 90-day hot retention and 13-month cold retention. Anomaly detection flags impossible-travel events, off-hours privileged access, and lateral-movement patterns for SOC review.

Onboarding and offboarding

Access provisioning is triggered by an authoritative HR/contracts event and gated by completion of CS-01 Security Training. Offboarding revokes all credentials within 4 business hours of separation; for involuntary terminations, revocation is within 60 minutes.

/CONTROLLED_DOCUMENT

This document is the official, controlled version of CS-03 — Network Access Control Policy. Printed or downloaded copies are uncontrolled. Questions about this document should be directed to compliance@alexasecurity.net.

VERSION

2026.1

REVIEWED

April 1, 2026

NEXT REVIEW

Annual